Opens in a new tab
vmblog logo 2024 wht (updated)

DXC Technology on AI-Powered Security, Zero Trust Evolution, and Turning Cybersecurity into a Business Accelerator – VMblog QA

Share: 

David Marshall | Published: October 24, 2025

 

As cyber threats continue to escalate in both volume and sophistication, organizations are rethinking their approach to security�not just as a defensive necessity, but as a strategic business enabler. DXC Technology, which manages over 4.5 million daily security threats across hundreds of global enterprises, is at the forefront of this transformation. With a partner-agnostic philosophy and a commitment to tailoring solutions to each client’s unique risk profile, DXC is helping organizations move beyond vendor lock-in to embrace the best-of-breed technologies that drive both security and innovation. The company’s recent partnership with agentic security leader 7AI has already delivered impressive results, including an 80% reduction in analyst-reviewed tickets and significant improvements in mean time to respond.

In this exclusive Q&A, Dawn-Marie Vaughan, Cybersecurity Global Offering Lead at DXC Technology, shares insights on how autonomous AI agents are revolutionizing security operations while keeping humans firmly in control, why identity has become the new security perimeter in Zero Trust architectures, and how DXC’s own 90-day transformation to a virtual-first security model blocked 9.2 million threats without disrupting productivity for 130,000 users. Vaughan also discusses the evolving digital risk landscape, the critical role of AI in both enabling attackers and empowering defenders, and why the most transformative cybersecurity strategies begin with candid conversations about challenges and co-created solutions.

++ 

VMblog: Let’s start with the big picture – what does DXC do in the cybersecurity space and what do you think sets you apart?  

Dawn-Marie Vaughan: DXC operates across the cybersecurity landscape at a truly global scale, delivering end-to-end solutions that are designed to secure and accelerate business outcomes. Our approach is rooted in understanding the broader business context-ensuring that cybersecurity is not just a protective layer but a strategic enabler of innovation and operational resilience.  

What sets DXC apart is our partner- and tool-agnostic philosophy. We don’t believe in one-size-fits-all solutions or vendor lock-in. Instead, we tailor our cybersecurity strategies to meet the specific needs of each customer, ensuring they get 100% of what they need-not just what a single vendor can offer. This flexibility allows us to integrate the best technologies available, aligned to each organization’s unique risk profile and business goals.  

We actively leverage the full spectrum of capabilities from our trusted partners, bringing their advanced AI and agentic automation features into our security operations. This ensures our customers benefit from the most effective tools and applications available, without compromise. Whether it’s endpoint protection, threat intelligence, cloud-native security, or identity management, we orchestrate the right technologies to deliver speed, precision, and resilience.  

Our scale also matters. With one of the largest global footprints in cybersecurity, we manage over 4.5 million daily security threats across hundreds of enterprises. This real-world data environment fuels our ability to deliver actionable insights and continuously evolve our security capabilities. 

VMblog: DXC recently announced a new partnership with agentic security leader 7AI. What’s most exciting to you about the partnership? What benefits is DXC seeing as a customer?  

Vaughan: This partnership represents a pivotal shift in how security operations centers (SOCs) function. By integrating autonomous capabilities into our SOC workflows, we’ve reimagined how repetitive tasks-such as alert triage, threat investigation, and incident response-are handled. The result is a more agile and efficient SOC, where human analysts are empowered to focus on strategic, high-value work.  

We are seeing measurable benefits already. Investigations that once took hours are now resolved in minutes, with significant reductions in the volume of tickets requiring manual review. With our Tier 1 analysts, we’ve seen up to an 80% reduction in analyst-reviewed tickets and a 67-68% improvement in mean time to respond (MTTR). These are the kinds of metrics that resonate with CIOs and CISOs looking to drive performance and resilience. 

However, while autonomous systems handle the heavy lifting, human analysts remain in control-making final decisions, validating high-risk actions, and applying strategic verdicts. This “human in the loop” balance ensures speed and scale without compromising governance. The L1 analysts still control the ultimate verdict, the decision whether to escalate or not. 

VMblog: The 7AI partnership addresses the skills gap challenge within cybersecurity – how do you see human work being impacted by 7AI AI agents?  

Vaughan: The cybersecurity skills gap has long been a challenge-not just in sourcing talent, but in justifying the investment needed to scale teams. By automating routine tasks, our SOCs free up time for our teams to focus on complex threat hunting, incident response, and proactive risk mitigation. This shift allows teams to stay sharp, continuously upskill, and operate at a higher strategic level. 

We are actively assessing our L1 – L2 positions, to align what the L2-L3 workload will look like in the near future and the additional skillset that will be required. We know it will free up time for our team to do more high value work but also to allow them to focus their attention to critical thinking, predicting what the adversaries are trying to do by linking exploits together to launch an attack. It’s very clear: scale is no longer the bottleneck. What’s needed now are curious, creative, strategic thinkers who can teach and govern these systems effectively.  

Additionally, new roles will surface and continue to emerge as we learn and adapt to the full spectrum of the intelligence that AI can apply to cybersecurity. Ethics and compliance will play an enormous role in the future, across all AI applied technology. Securing AI will be increasingly important as much as it will be in helping us use AI to secure the world. 

VMblog: You’ve also recently examined the current state of zero trust within enterprises – how has zero trust evolved and what is its future path?  

Vaughan: Zero Trust is no longer a perimeter security layer – it’s an entire framework across all things related to cybersecurity. It has evolved from a perimeter-based model to one that must now operate in a dynamic, borderless, AI-driven environment. Our recent research shows that legacy architectures are a major barrier to progress, with 66% of organizations citing them as a limiting factor.  

Today, identity is the new perimeter. With 85% of breaches occurring in the identity and verification space, a robust identity management platform is foundational to any Zero Trust strategy. Our data shows that organizations with centralized identity platforms are 72% more likely to maintain and evolve their Zero Trust posture.  

Looking ahead, AI will play a central role in Zero Trust frameworks-particularly in areas like micro segmentation, risk-based access, and reducing false positives. While adoption is still maturing, the benefits are already evident. DXC is helping customers navigate this transition with tailored roadmaps that address technical complexity, privacy concerns, and evolving adversarial tactics. 

VMblog: How can cybersecurity be a ‘business booster’. Can you walk us through an example of that?  

Vaughan: Cybersecurity, when done right, is a catalyst for innovation. It’s not about saying “no”-it’s about enabling organizations to move faster and more confidently. It’s also all about the user experience. The CISO doesn’t want to be responsible for slowing down the entire workforce with clunky MFAs, for example. Modern architecture and applications can significantly reduce the disruption and improve security at the same time.   

Take DXC’s own virtual-first strategy. We transitioned from a traditional firewall and VPN model to an identity-centric Zero Trust architecture. By deploying an inline security cloud platform, we secured internet and SaaS access for 130,000 global users, detected 1.3 billion policy violations, and blocked 9.2 million threats in a single quarter-all without disrupting productivity.  

This transformation was completed in just 90 days. And while continuous verification can introduce friction, our research shows that context-aware access and user feedback loops significantly reduce disruption. Our own experience as “customer zero” allows us to lead by example-bringing proven, real-world use cases to our clients across all industries. 

VMblog: How do you think AI will impact the cybersecurity space?  

Vaughan: AI is reshaping the threat landscape. Threat actors are using it to craft sophisticated phishing campaigns, generate deepfakes, and develop malware that adapts to its environment in real time and can correct its own errors. These capabilities are accelerating the scale and complexity of attacks.  

But AI is also a powerful tool for defenders. At DXC, we’re embedding AI across every pillar of cybersecurity-from identity and device to network, applications, and data. AI helps reduce false positives, automate response, and enhance visibility across environments.  

What sets DXC apart is our proactive stance. We’re not just observing the rise of AI-we’re integrating it into our operations, enabling our customers to adopt AI-enhanced cybersecurity strategies that deliver measurable outcomes today while preparing them for tomorrow.   

I’m fortunate to be able to leverage my coworkers in other areas of our business that are experimenting with innovative applications of AI; including digital twins which is of particular interest to me and the cyber team. It is revolutionizing offense security in so many ways; war games, tabletop exercises, and vulnerability research. For example, having the ability to pen testing an entire complex application or a cobbled together infrastructure will finally surface vulnerabilities that have existed for years. Currently, sections of an app or sub-set of a system are tested independently, and there are gaps that are intrinsically missed. With a digital twin, the entire eco system could be tested without disruption or inaccessibility. 

VMblog: Looking ahead, how do you see the digital risk landscape evolving, and what should business and IT leaders be doing now to stay ahead of emerging threats?  

Vaughan: The scale and sophistication of cyberattacks will continue to grow. To stay ahead, organizations must focus on areas with clear ROI-like modernizing their SOCs and investing in advanced penetration testing.  

At DXC, we advise leaders to start by defining their AI strategy. That means asking: 

  • How can we develop a sound AI preparedness approach? 
  • How do we defend against AI-driven threats? 
  • How do we ensure visibility and interoperability across our environment? 
  • How do we secure AI?  

By answering these questions, organizations can identify high-impact opportunities, evaluate strategic partnerships, and foster a culture of continuous improvement. Most importantly, this journey begins with open dialogue. The most transformative cybersecurity strategies we’ve seen start with candid conversations-where challenges are shared, and solutions are co-created. AND… humans in the loop, at every juncture.

##